Impersonation Vulnerability in FreshRSS Self-Hosted Feed Aggregator
CVE-2025-46341

7.1HIGH

Key Information:

Vendor

Freshrss

Status
Vendor
CVE Published:
4 June 2025

What is CVE-2025-46341?

FreshRSS, a self-hosted RSS feed aggregator, is susceptible to a user impersonation vulnerability when utilizing HTTP authentication through a reverse proxy. Attackers can deceive the system into believing they are another user by manipulating the Remote-User or X-WebAuth-User headers during crafted requests. To exploit this issue, they need prior knowledge of the FreshRSS instance’s IP address, the admin's username, and must possess an account on the system. This vulnerability facilitates unauthorized access to internal services and may enable privilege escalation under certain configurations. FreshRSS version 1.26.2 addresses this flaw, highlighting the importance of prompt updates to safeguard user accounts.

Affected Version(s)

FreshRSS < 1.26.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.